
Profile Directory – Filter Security & Risk Analysis
wordpress.org/plugins/codedropz-filter-profile-directoryA simple profile directory plugin and easy to manage using custom postype with custom filter.
Is Profile Directory – Filter Safe to Use in 2026?
Generally Safe
Score 85/100Profile Directory – Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "codedropz-filter-profile-directory" v1.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The use of prepared statements for all SQL queries and the presence of nonce checks are positive security indicators. However, the low percentage of properly escaped output (62%) is a notable concern, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care in the remaining 38% of output operations. The lack of capability checks on AJAX handlers, while the attack surface is small and all are reported as protected, could be a minor point of improvement. The plugin's vulnerability history is clean, with no recorded CVEs, which indicates a good track record so far, but this should not lead to complacency regarding potential future undiscovered issues. Overall, the plugin shows a commitment to secure coding practices, but the output escaping requires attention to mitigate potential XSS risks.
Key Concerns
- Low percentage of properly escaped output
Profile Directory – Filter Security Vulnerabilities
Profile Directory – Filter Code Analysis
Output Escaping
Data Flow Analysis
Profile Directory – Filter Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Profile Directory – Filter Maintenance & Trust
Maintenance Signals
Community Trust
Profile Directory – Filter Alternatives
WP Ultimate Post Grid
wp-ultimate-post-grid
Easily create filterable responsive grids for your posts, pages or custom post types
A-2-Z Alphabetical Archive Links
a2z-alphabetical-archive-links
Create and display a list of first characters for post/cpt titles which link to an archive of the posts/cpts that begin with that character.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Profile Directory – Filter Developer Profile
4 plugins · 65K total installs
How We Detect Profile Directory – Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codedropz-filter-profile-directory/css/pdfi_style.css/wp-content/plugins/codedropz-filter-profile-directory/js/pdfi_script.js/wp-content/plugins/codedropz-filter-profile-directory/css/admin/pdfi_admin.css/wp-content/plugins/codedropz-filter-profile-directory/js/pdfi_script.jscodedropz-filter-profile-directory/css/pdfi_style.css?v=codedropz-filter-profile-directory/js/pdfi_script.js?v=HTML / DOM Fingerprints
pdfi-profile-wrapperpdfi-load-more This protect the plugin file from direct access Define our Plugin Version Directory Separator Define our constant Plugin Name +41 moredata-id="p-filter-content"data-action="load-more"pdfi_ojbectpdfi_options<div class="pdfi-profile-wrapper"><div data-id="p-filter-content" class="<div class="pdfi-load-more"><a href="javascript:void(0)" class="btn" data-action="load-more">